I was going to spend today writing about something else entirely, had a whole draft half typed about switching my RSS reader again (dont ask, its a whole thing), and then Friday happened and I scrapped it. If you have any friends in IT you probably already know what Im talking about, because mine did not stop texting me all weekend.
Short version for anyone who managed to stay off Twitter since Friday: theres a piece of ransomware going around called WannaCry, and it had an absolutely brutal couple of days. It hit hospitals here in the UK hard enough that some NHS trusts were diverting ambulances and cancelling surgeries that werent emergencies. It also landed on FedEx systems, Telefonica in Spain, Renault plants, Deutsche Bahn departure boards in Germany. Not a small thing. Dozens of countries by Saturday morning.
Whats actually eating at me isnt the scale of it, its one specific detail that came out over the weekend, and I think its more interesting than the attack itself.
The malware spreads using an exploit called EternalBlue, which as far as anyone can tell was built by the NSA and then dumped online last month by a group calling themselves the Shadow Brokers. Microsoft had already patched the underlying Windows SMB vulnerability back in March, so any machine thats actually kept up to date was fine. Which, sure, tells you almost everything you need to know about why this spread the way it did. A shocking number of machines out there, including ones running hospital imaging equipment apparently, are on Windows XP or just never got the March update installed. Microsoft ended up doing something they basically never do and pushed out a patch for XP this weekend even though that OS has been out of support for three years now.
But the part I keep coming back to is a 22-year-old security researcher in the UK who goes by MalwareTech online, whose name is apparently Marcus Hutchins. He was picking apart a sample of the malware Friday and noticed it was making a request to an ugly, long, nonsense domain name before it did anything else. Nobody owned that domain. So he registered it. For about ten pounds, ten dollars and change, the kind of thing you do on a whim because you want the traffic logs for research.
Turns out that domain was a kill switch, whether intentionally built in by the malware author or as some kind of sandbox-detection check gone sideways, nobody's fully sure yet. The malware was written to check if that domain resolved, and if it did, to stop spreading. By registering it, Hutchins accidentally flipped the switch. He didnt know that was what hed find when he bought it. He found out because the spread slowed down almost immediately after, and then had to piece together what had actually happened from watching his own traffic logs spike into the millions of requests a minute.
I dont know why that detail gets me more than the hospital stuff, honestly, maybe because everything else about this story is grim and inevitable feeling (unpatched systems, leaked government exploits, hospitals running software from 2001) and this one part of it is just a person being curious on a Friday afternoon and stumbling into stopping something. Not a security firm with a war room. Not a government response. A guy with a research blog and ten bucks.
Worth saying clearly: this isnt over, and registering that domain doesnt undo any of the encrypted files sitting on machines right now. Somebody could tweak the code and cut the kill switch out entirely, and I'd be surprised if that doesnt happen this week. If youre reading this on a Windows machine you havent updated in a while, do it today, not tomorrow. Im saying that as someone who ignores update prompts for weeks at a stretch too, so believe me I get the appeal of just clicking remind me later. I did it again Thursday, actually, which is a fun thing to admit given what Im writing about right now.
Anyway. Go patch your machine. Ill get back to the RSS reader post another day, its not going anywhere.